节点文献

Windows安全基线研究

Research on Windows Security Baseline

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 卿斯汉曾山松杜超

【Author】 QING Si-han;ZENG Shan-song;DU Chao;School of Software and Microelectronics, Peking University;Institute of Software, Chinese Academy of Sciences;State Key Laboratory of Information Security;

【机构】 北京大学软件与微电子学院中国科学院软件研究所信息安全国家重点实验室

【摘要】 随着互联网应用的快速发展,信息系统的安全性问题日益突出,安全基线的概念、技术与应用就更加重要。安全基线是微软安全生态系统中的一个重要组成部分,它通过安全合规管理器(SCM)以基线的形式判断用户的应用环境安全是否达标,提供一个信息系统所需的最基本的安全保证。安全基线的概念源于微软为美国空军实施的安全配置方案,最终为美国政府机构所采纳,作为国家标准实施。文章对Windows安全基线的由来与发展、安全合规管理器(SCM)、安全基线的基本概念和实现原理、安全基线的部署与安全策略设置、Windows 8.1的安全基线更新等进行讨论与分析。Windows安全基线的概念可以方便地推广到更加广泛的应用场合,如Linux操作系统。

【Abstract】 With the rapid development of internet applications, the security issues of information systems have become increasingly prominent, and consequently the concept, methodology and application of security baseline have become more important. Security baseline is an important part of Microsoft’s security ecosystem, by the use of security compliance manager(SCM) which is able to determine whether the security requirements of users’ application environment are met, providing a basic security assurance for an information system. The concept of security baseline originally coming from the Microsoft’s security configuration initiative for the US Air Force, eventually had been accepted by the US government, and been deployed as national standards. This paper discusses and analyzes the origin and progress of Windows security baseline, security compliance manager, the basic concept and implementation rationale of security baseline, deployment and security policy settings of security baseline, and update of security baseline for Windows 8.1. The concept of Windows Security Baseline can be easily extended to a wide range of applications, such as Linux OS.

【基金】 国家自然科学基金[61170282]
  • 【文献出处】 信息网络安全 ,Netinfo Security , 编辑部邮箱 ,2015年03期
  • 【分类号】TP316.7;TP309
  • 【被引频次】11
  • 【下载频次】245
节点文献中: 

本文链接的文献网络图示:

本文的引文网络